How to Create Fine Gained Password Policies

How to Create Fine Gained Password Policies

How to Create a Fine-Grained Password Policy in Active Directory

Before the launch of Windows Server 2008, administrators could apply only one password and account lockout policy to the entire user base in the organization. If the administrators wanted to enforce stricter password policies for just a subset of critical users in the organization, they'd have to organize them in a separate domain and apply a different domain policy.

However, with the launch of Windows Server 2008, Microsoft introduced fine-grained password policies. This helped administrators enforce multiple password and account lockout policies to different sets of users within a single domain.
 
This article walks you through how you can configure fine-grained password policies in your Windows environment.To create a new fine-grained password policy using ADC, follow these steps: 
  1. Open Active Directory Administrative Center and click on your domain.
  2. Click on the System folder and navigate to the Password Settings Container.
  3. To create a new password policy, click on New in the right side menu.
  4. Configure the required policy settings and apply it to any users or groups.
  5. To apply the policy to a group or users, click on Add
  6. Select the required users or group and click OK
  7. Click OK on the Create Password Settings screen. 
This will create a fine-grained password policy and apply it to the specified users.